Releases: fireblocks/java-sdk
Release list
v33.0.0
Changelog
2026-09-30
Breaking Change
Lower limit on UTXOs per labelling request
Products: UTXO Management (Beta)
Scope: API + SDKs
-
What's new
The maximum number of UTXO identifiers accepted in a single labelling request has been reduced from 200 to 50. -
Impact
Integrations submitting more than 50 identifiers in one request will need to split them into smaller batches.
Affected endpoints:
Stricter validation for UTXO transaction hashes
Products: UTXO Management (Beta)
Scope: API + SDKs
-
What's new
Transaction hashes used to identify UTXOs must now be lowercase hexadecimal and no longer than 64 characters; uppercase hashes are no longer matched. -
Impact
Integrations sending uppercase or malformed transaction hashes will need to update their values to match this stricter format.
Affected endpoints:
Update required Canton onboarding parties
Products: Canton (Beta)
Scope: API + SDKs
-
What's new
Onboarding a Canton participant no longer requires a provider party id, and now requires an upgrader party id used for model upgrade authority. -
Impact
Existing integrations must remove the provider party id and add the new upgrader party id when onboarding a Canton participant.
Affected endpoints:
Simplify allocation withdrawal request
Products: Canton (Beta)
Scope: API + SDKs
-
What's new
Withdrawing an allocation no longer requires specifying the vault account or asset, since these are derived automatically from the original transaction. -
Impact
Existing integrations that sendvaultAccountIdorassetwhen withdrawing an allocation will need to remove those fields.
Affected endpoints:
Rename Canton offer domain values
Products: Canton (Beta)
Scope: API + SDKs
-
What's new
The values identifying an offer's domain when responding to a Canton offer have changed from plural to singular form. -
Impact
Existing integrations that reference the plural domain values will need to be updated to use the new singular values.
Affected endpoints:
Add structured time-in-force type field
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
The time-in-force value for limit orders is now a structured object with a type field instead of a plain text value. -
Impact
Existing integrations that use fill-or-kill time-in-force will need to update how they specify it.
Affected endpoints:
OAuth credentials reference an mTLS configuration
Products: Webhooks V2
Scope: API + SDKs
-
What's new
OAuth credentials now point at an mTLS configuration bywebhookMtlsId, the same field and the same resource webhooks use, instead of carrying their own certificate. One certificate signed fromGET /webhooks_settings/mtls_csrcan serve both the token endpoint and the receiver. Deleting an mTLS configuration is refused while OAuth credentials reference it as well as webhooks;forceDelete=truedetaches both and returnsdetachedWebhookOauthIdsalongsidedetachedWebhookIds. -
Impact
Customers configure and rotate the certificate for their token endpoint the same way as for delivery, and can share one configuration between them. Existing certificates on OAuth credentials are migrated to an mTLS configuration automatically.
Affected endpoints:
- Create OAuth credentials
- Update OAuth credentials
- Get OAuth credentials by id
- Get all OAuth credentials
- Delete an mTLS configuration
Manage mTLS client certificates as their own resource
Products: Webhooks V2
Scope: API + SDKs
-
What's new
The signed client certificate moves off the webhook and onto its own resource under/webhooks_settings/mtls, with endpoints to upload, list, read, replace and delete one. Several webhooks can share a configuration, so replacing the certificate is a single call instead of one per webhook. A webhook now references it bywebhookMtlsId, alongsidewebhookOauthId. Deleting a configuration is refused with409 Conflictwhile any webhook still references it, unlessforceDelete=trueis passed, which detaches those webhooks and returns their ids. -
Impact
Customers rotating an mTLS certificate used by several webhooks do it once, and can see which webhooks a configuration is in use by before removing it. Existing callers that set or read the certificate on the webhook itself must move to the new field names.
Affected endpoints:
- Create an mTLS configuration
- List the uploaded mTLS configurations
- Get an mTLS configuration by id
- Update an mTLS configuration
- Delete an mTLS configuration
Change travelRuleProviders from fixed enum to string
Products: Compliance
Scope: API + SDKs
-
What's new
Changes the travel rule provider field from a fixed enum to a plain string to support dynamic provider lists and match actual API wire format. -
Impact
Customers using strict enum validation must update their code to handle any string value.
Affected endpoints:
Add required proofOfOwnershipAvailable field to legal entity
Products: Compliance
Scope: API + SDKs
-
What's new
Adds a required boolean field indicating whether Proof of Ownership creation is available for a given address, and updates example values for travel rule providers. -
Impact
Customers must update their models to include this new required field in legal entity responses.
Affected endpoints:
Added
Detailed errors for failed UTXO labelling
Products: UTXO Management (Beta)
Scope: API + SDKs
-
What's new
When a UTXO labelling request can't be completed, the response now lists each identifier that blocked it along with the specific reason it failed. -
Impact
Customers can identify exactly which identifiers failed and why, and resubmit the request with only the valid ones.
Affected endpoints:
Delete console users via API (beta)
Products: Console User
Scope: API + SDKs
-
What's new
Adds an endpoint to request deletion of a console user, which goes through the workspace's configured approval policy before the user is removed. -
Impact
Customers can trigger console user deletion programmatically instead of using the console UI; this is a non-breaking addition and existing integrations continue to work.
Affected endpoints:
- [Request d...
v32.0.0
Changelog
2026-09-23
SDK and CLI updates: TypeScript SDK v32.0.0 • Python SDK v32.0.0 • Java SDK v32.0.0 • CLI v12.0.0
Breaking Change
Move the mTLS CSR endpoint under webhook settings and add ECDSA support
Products: Webhooks V2
Scope: API + SDKs
-
What's new
The mTLS CSR endpoint moves fromGET /webhooks/mtls/csrtoGET /webhooks_settings/mtls_csr, alongside the other webhook settings resources. It also accepts an optionalkeyAlgorithmquery parameter,RSAorECDSA, and echoes the algorithm the CSR was issued for back on the response. -
Impact
Customers can request ECDSA-based CSRs for smaller, faster certificate issuance. Callers of the previous path must move to the new one.
Affected endpoints:
Added
Add transfer status to internal transfers
Products: Exchange accounts
Scope: API + SDKs
-
What's new
Internal transfer responses now include an optionalstatusfield and asystemMessagesarray describing the health of the transfer, populated when the transfer is processed through the transaction manager flow. -
Impact
Customers can see the outcome and any system messages for an internal transfer directly in the response; existing integrations continue to work since both fields are optional.
Affected endpoints:
Add Compliance Orchestrator API (private beta)
Products: Compliance Orchestrator
Scope: API + SDKs
-
What's new
Adds new Compliance Orchestrator endpoints for triggering on-demand compliance screenings, retrieving screening results, and managing workflow configurations. -
Impact
Customers enrolled in the private beta can programmatically screen addresses and transactions before they exist on-chain.
Affected endpoints:
- Trigger a Compliance Orchestrator screening
- Get a Compliance Orchestrator screening's result
- Get a Compliance Orchestrator workflow
- Update a Compliance Orchestrator workflow's status
Add approval request approve endpoint (beta)
Products: Approvals (Beta)
Scope: API + SDKs
-
What's new
Adds a beta endpoint to approve a pending approval request by signing the request's signable data with a registered approval API key. -
Impact
Customers can programmatically approve approval requests through the API instead of using the Console.
Affected endpoints:
Add approval key management endpoints (beta)
Products: Approvals (Beta)
Scope: API + SDKs
-
What's new
Adds beta endpoints to register, list, and delete approval public keys for API users, enabling cryptographic signing of approval requests. -
Impact
Customers can manage approval signing keys for API users through the API.
Affected endpoints:
Add Compliance Orchestrator screening endpoints (beta)
Products: Compliance Orchestrator
Scope: API + SDKs
-
What's new
Adds private beta endpoints to trigger on-demand compliance screenings against active workflows and retrieve screening results with audit logs. -
Impact
Customers can programmatically run compliance screenings before transactions exist on-chain.
Affected endpoints:
Changed
Token request authorization header rules
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Anauthorizationheader can be set on the token request to your authorization server when credentials are sent in the request body, and is rejected when they are sent in that header instead. -
Impact
Customers whose token endpoint sits behind a gateway can supply their own authorization header, while conflicting combinations are rejected up front.
Affected endpoints:
Custom header limit counted per name
Products: Webhooks V2
Scope: API + SDKs
-
What's new
The ten-header limit on webhook custom headers is counted per header name rather than per delivered header line, and OAuth bearer tokens are cached until they expire instead of being fetched for every delivery. -
Impact
Customers can attach multi-value headers without consuming the limit, and authorization servers receive far fewer token requests.
Affected endpoints:
Authorization header and OAuth are exclusive
Products: Webhooks V2
Scope: API + SDKs
-
What's new
A webhook can use either OAuth credentials or its ownauthorizationcustom header, but not both, and the header now accepts only a single string value. -
Impact
Customers should configure a webhook with either OAuth credentials or anauthorizationheader; combining the two is not supported.
Affected endpoints:
Clear OAuth credential maps with a null value
Products: Webhooks V2
Scope: API + SDKs
-
What's new
The custom claims, body parameters and headers on stored OAuth credentials can now be emptied in one step by setting the whole field tonull, in addition to deleting individual keys. -
Impact
Customers can clear an entire map without listing every key, and requests that previously failed with a validation error now succeed.
Affected endpoints:
Fixed
Clarify contract parameter value types
Products: Contract Interactions, Contract Templates, Deployed Contracts, Tokenization
Scope: API + SDKs
-
What's new
The documentation for a contract parameter'svaluenow explains that its shape follows the ABI type: strings for text and addresses, numbers for integers, booleans, arrays, and nested entries for tuples. -
Impact
Customers get accurate guidance on how to supply non-string parameter values when interacting with contracts.
Affected endpoints:
v31.0.0
Changelog
2026-09-15
SDK and CLI updates: TypeScript SDK v31.0.0 • Python SDK v31.0.0 • Java SDK v31.0.0 • CLI v11.0.0
Breaking Change
Remove inline webhook OAuth schemas
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Removes the deprecated inline OAuth configuration schema in favor of the shared OAuth credentials model managed via dedicated endpoints. Removes the deprecated inline OAuth response schema in favor of the shared OAuth credentials model managed via dedicated endpoints. -
Impact
Customers must migrate from inline OAuth configuration to using shared OAuth credentials referenced by ID.
Affected endpoints:
Replace inline oauth object with webhookOauthId reference
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Replaces the inlineoauthconfiguration object with awebhookOauthIdfield that references shared OAuth credentials managed via the dedicated OAuth credentials endpoints. Replaces the inlineoauthresponse object with awebhookOauthIdfield that references shared OAuth credentials managed via the dedicated OAuth credentials endpoints. -
Impact
Customers must update webhook creation requests to usewebhookOauthIdinstead of the inlineoauthobject. Customers must update webhook update requests to usewebhookOauthIdinstead of the inlineoauthobject. Customers must update code that reads webhook responses to usewebhookOauthIdinstead of the inlineoauthobject.
Affected endpoints:
Rename webhook OAuth operation IDs and schemas
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Renames OAuth-related operation IDs and schema references fromOAuthtoOauthcasing to ensure SDK generators produce consistent method and class names instead of awkwardo_authidentifiers. -
Impact
Customers using SDKs must update their code to reference the new method and class names.
Affected endpoints:
- Create OAuth credentials
- Get all OAuth credentials
- Get OAuth credentials by id
- Update OAuth credentials
- Delete OAuth credentials
Added
Add supported fiat account types to FiatAccountType
Products: Fiat accounts
Scope: API + SDKs
-
What's new
Expands theFiatAccountTypeenum to include all supported fiat banking providers (BLINC, CrossRiver, Fifth Third, Kingdom Bank, Lynq, N3XT, Sygnum Connect, Transfero, and more) plus anOTHERfallback for unrecognized types. -
Impact
Customers receive more specific fiat account type values in API responses.
Affected endpoints:
Add credentials_replaced webhook events
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds two new event types to the webhook events enum:exchange_account.credentials_replacedandconnected_account.credentials_replaced, emitted when the API credentials of an exchange or connected account are replaced. -
Impact
Customers can now subscribe to notifications when account API credentials are replaced.
Affected endpoints:
- Get all notifications by webhook id
- Create a new webhook
- Get all webhooks
- Get notification by id
- Resend notifications by query
- Resend failed notifications
- Get webhook by id
- Update webhook
- Delete webhook
Add connected account credentials update endpoint (beta)
Products: Connected Accounts (Beta)
Scope: API + SDKs
-
What's new
Adds a beta endpoint to replace API credentials for connected accounts, with pending mobile approval workflow and webhook notifications. -
Impact
Customers can programmatically update connected account API credentials through the API.
Affected endpoints:
Add reject approval request endpoint (beta)
Products: Approvals (Beta)
Scope: API + SDKs
-
What's new
Adds a beta endpoint to reject a pending approval request as the authenticated API user without requiring a signature. -
Impact
Customers can programmatically reject pending approval requests through the API.
Affected endpoints:
Changed
Allow Authorization header in webhook custom headers
Products: Webhooks V2
Scope: API + SDKs
-
What's new
TheAuthorizationheader is no longer reserved for webhooks. When OAuth credentials are attached, both the custom Authorization value and the bearer token are sent as separate header lines. -
Impact
Customers can now provide their ownAuthorizationheader value for webhook endpoints that require static credentials.
Affected endpoints:
Fixed
Correct custom header value size limit documentation
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Corrects the webhook custom header documentation to reflect the actual size limit: there is no per-value character limit, and the whole map must be under 16 KB of UTF-8. -
Impact
Customers can now rely on accurate documentation showing that individual header values have no length limit, with only the 16 KB total map size constraint.
Affected endpoints:
v30.0.0
Changelog
2026-09-08
SDK and CLI updates: TypeScript SDK v30.0.0 • Python SDK v30.0.0 • Java SDK v30.0.0 • CLI v10.0.0
Breaking Change
Add OAuth auth methods and custom fields support
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds documentation for merge semantics when updating OAuth credential custom fields, where keys with values are upserted and keys with null are deleted. AddsauthMethodfield andcustomJwtClaims,customBodyParams,customHeadersfields to OAuth credential creation requests. Improves description clarity for the delete OAuth credentials response schema. AddsauthMethodfield andcustomJwtClaims,customBodyParams,customHeadersupdate schemas with merge semantics documentation. AddsauthMethodas a required response field and read-only arrays forcustomJwtClaims,customBodyParams,customHeadersshowing configured key names without values. Adds schema for custom body parameters on OAuth token requests, supporting string values and write-only storage with read-only name arrays. Adds schema for updating custom body parameters with merge semantics where null deletes a parameter. Adds schema for custom HTTP headers on OAuth token requests, supporting string values with case-insensitive matching and write-only storage. Adds schema for updating custom token request headers with merge semantics where null deletes a header. Adds schema for custom JWT claims used withclient_secret_jwtauthentication, supporting any JSON type except null with write-only storage. Adds schema for updating custom JWT claims with merge semantics where null deletes a claim. -
Impact
Customers can use key-by-key merge behavior when updating OAuth credential custom fields.
Affected endpoints:
Added
Python SDK idle connection timeout support
Products:
Scope: Python-SDK
-
What's new
Connections idle for more than 30 seconds are now reopened instead of reused. the limit is configurable withconnection_idle_timeout_sec. -
Impact
Existing integrations continue to work unchanged.
Affected endpoints:
Add Canton calls and offer response endpoints (beta)
Products: Canton (Beta)
Scope: API + SDKs
-
What's new
Publishes the beta API contract for Canton network calls and offer responses - participant onboarding, end-investor management, allocation operations, and transfer workflows. The endpoints are internal-only in this release and the downstream handlers are not implemented yet. -
Impact
No customer-facing change yet. The contract is published so SDKs and integrations can be built against it; the routes are gated behind an internal feature flag and unimplemented domains return HTTP 501.
Affected endpoints:
Add approval requests endpoints (beta)
Products: Approvals (Beta)
Scope: API + SDKs
-
What's new
Adds beta endpoints to list pending approval requests and retrieve individual requests by ID, with support for pagination, quorum status, and cross-user or workspace-wide queries. -
Impact
Customers can programmatically access and monitor approval requests through the API.
Affected endpoints:
Add webhook OAuth credentials management endpoints
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds endpoints to create, list, retrieve, update, and delete reusable OAuth client credential sets that can be shared across multiple webhooks for centralized secret rotation. -
Impact
Customers can manage OAuth credentials separately from webhooks, enabling easier credential rotation across multiple webhook configurations.
Affected endpoints:
- Create OAuth credentials
- Get all OAuth credentials
- Get OAuth credentials by id
- Update OAuth credentials
- Delete OAuth credentials
Add hasNativeAssets field to UTXO outputs
Products: UTXO Management (Beta)
Scope: API + SDKs
-
What's new
Adds an optional boolean field to indicate whether a UTXO carries Cardano native assets (tokens). -
Impact
Customers can now detect encumbered ADA outputs when managing UTXO-based deposits.
Affected endpoints:
Add completionTime to staking transactions
Products: Staking
Scope: API + SDKs
-
What's new
Adds an optionalcompletionTimefield to PositionRelatedTransaction that indicates when Cosmos unbonding is scheduled to end. -
Impact
Integrators can track when unbonding funds will be released on Cosmos-family chains.
Affected endpoints:
Add 5 missing webhook event types to WebhookEvent enum
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds 5 new event types to the webhook events enum:transaction.alert.stuck,vault_account.bulk_create_job_started,vault_account.bulk_create_job_ended,vault_account.asset.bulk_add_job_started, andvault_account.asset.bulk_add_job_ended, bringing the enum in sync with deployed webhook-events 1.32.0. -
Impact
Customers can now subscribe to stuck transaction alerts and bulk vault account/asset job events via the API.
Affected endpoints:
- Get all notifications by webhook id
- Create a new webhook
- Get all webhooks
- Get notification by id
- Resend notifications by query
- Resend failed notifications
- Get webhook by id
- Update webhook
- Delete webhook
Add requestedFeeCurrency to transaction responses
Products: Transactions
Scope: API + SDKs
-
What's new
Adds therequestedFeeCurrencyfield showing which asset was requested at transaction creation to pay Tempo transaction fees. -
Impact
Customers can now see which fee-paying asset was originally requested when retrieving transaction details.
Affected endpoints:
- Get a specific transaction by external transaction ID
- Get a specific transaction by Fireblocks transaction ID
- Get transaction history
Changed
Add subProviders field to trading response schemas
Products: Trading (Beta)
Scope: API + SDKs
- What's new
Introduces response-only schema variants...
v29.0.0
Changelog
2026-09-01
Breaking Change
Fix validBefore/validAfter semantics in TRLink policy rules
Products: Transactions
Scope: API + SDKs
-
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps. -
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
- Get a specific transaction by external transaction ID
- Get a specific transaction by Fireblocks transaction ID
- Get transaction history
Fix validBefore/validAfter semantics in TRLink policy rules
Products: TRLink
Scope: API + SDKs
-
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps. -
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
Fix validBefore/validAfter semantics in TRLink policy rules
Products: Compliance
Scope: API + SDKs
-
What's new
Corrects the documentation for validBefore and validAfter fields to accurately describe their behavior as relative durations (seconds since wait/screening step started) rather than absolute Unix timestamps. -
Impact
Customers should update their implementations to use relative durations in seconds instead of Unix timestamps for these fields.
Affected endpoints:
Remove type field from security finding responses
Products: Security Posture Management
Scope: API + SDKs
-
What's new
Removes thetypefield from security finding schemas and updates example data to reflect a different finding scenario. -
Impact
Clients should no longer expect thetypefield in security finding responses and must update any code that depends on this field.
Affected endpoints:
Added
Add contacts list endpoint
Products: Contacts
Scope: API + SDKs
-
What's new
Adds a paginated endpoint to list workspace address book contacts with filtering by name, type, tags, access control, container, and archive status. -
Impact
Customers can programmatically retrieve and filter their address book contacts through the API.
Affected endpoints:
Add feeCurrency field for Tempo transactions (beta)
Products: Off exchanges, Transactions
Scope: API + SDKs
-
What's new
Adds an optionalfeeCurrencyfield to the transaction request schema, allowing users to specify which asset to use for paying network fees on Tempo-based transactions. -
Impact
Customers using Tempo can now control which asset pays transaction fees.
Affected endpoints:
Add AMOUNT_ABOVE_MAXIMUM failure reason
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
Adds a new enum value to indicate when a trading operation fails because the requested amount exceeds the maximum allowed limit. -
Impact
Customers can now programmatically detect and handle amount-too-large errors in trading operations.
Affected endpoints:
v28.0.0
Changelog
2026-08-26
Breaking Change
Remove deprecated FSPM category filter values
Products: Security Posture Management
Scope: API + SDKs
-
What's new
Removes ACCESS_CONTROL, ADMIN_MANAGEMENT, SECURITY, and CONFIGURATION values from the category filter parameter and updates the endpoint description text. -
Impact
API requests using the removed category filter values will receive validation errors.
Affected endpoints:
Added
Add FSPM security finding update endpoint
Products: Security Posture Management
Scope: API + SDKs
-
What's new
Adds an endpoint to accept or reopen FSPM security findings by setting the status to ACCEPTED or OPEN, with a required reason when accepting. -
Impact
Customers can programmatically manage FSPM finding statuses through the API.
Affected endpoints:
Add FSPM security finding details endpoint
Products: Security Posture Management
Scope: API + SDKs
-
What's new
Adds an endpoint to retrieve detailed information about a specific FSPM security finding by its ID, including compliance requirements, risk explanation, and mitigation guidance. -
Impact
Customers can now fetch complete details for individual security findings programmatically.
Affected endpoints:
v27.0.0
Changelog
2026-08-18
Breaking Change
Java SDK async methods no longer declare throws
Products:
Scope: Java-SDK
-
What's new
Asynchronous Java SDK methods no longer declare a checked exception that can never be thrown; call failures continue to arrive through the returned future. -
Impact
Code that wraps a Java SDK call in a try/catch for the API exception will stop compiling until that unreachable catch block is removed.
Affected endpoints:
Fix Travel Rule legalPerson name schema for IVMS101 compliance
Products: Off exchanges, Transactions, Travel Rule
Scope: API + SDKs
-
What's new
Fixes the Travel Rule legal person name schema to use the IVMS101-compliant array structure with proper name type codes (LEGL, SHRT, TRAD) instead of the incorrect flat object format. -
Impact
Customers must update Travel Rule integrations to use the new array-based name identifier structure.
Affected endpoints:
- Validate Full Travel Rule Transaction
- Create a new transaction
- Estimate transaction fee
- Add Collateral
- Remove Collateral
Fix Travel Rule legalPerson name schema for IVMS101 compliance
Products: Travel Rule
Scope: API + SDKs
-
What's new
Fixes the Travel Rule legal person name schema to use the IVMS101-compliant array structure with proper name type codes (LEGL, SHRT, TRAD) instead of the incorrect flat object format. -
Impact
Customers must update Travel Rule integrations to use the new array-based name identifier structure.
Affected endpoints:
Added
Add ETH staking consolidation and withdrawal ETA fields
Products: Staking
Scope: API + SDKs
-
What's new
Adds three new optional fields toEthereumBlockchainData:estimatedSourceExitTime,estimatedConsolidationTime, andestimatedWithdrawalTimeto surface timing estimates for in-flight ETH validator consolidations and withdrawals. -
Impact
Customers can now track estimated completion times for pending ETH staking consolidations and withdrawals via the API.
Affected endpoints:
Add gaslessInfo to transaction responses
Products: Transactions
Scope: API + SDKs
-
What's new
Adds a newgaslessInfoobject to transaction responses containing relay and meta-transaction details including tenant and vault account information. -
Impact
Customers can identify meta-transactions and see which relay tenant sponsored the gas fees.
Affected endpoints:
- Get a specific transaction by external transaction ID
- Get a specific transaction by Fireblocks transaction ID
- Get transaction history
Add new ReasonForPaymentEnum values
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
Adds three new payment reason values:CORPORATE_INVESTMENT,INTER_COMPANY_TRANSFER, andOFFICE_OPERATING_EXPENSESto support additional corporate payment use cases. -
Impact
Customers can now specify additional payment reasons when creating trading orders.
Affected endpoints:
Add FSPM security findings endpoint
Products: Security Posture Management
Scope: API + SDKs
-
What's new
Adds an endpoint to retrieve paginated security posture findings for a workspace, with filtering by severity, category, and status. -
Impact
Customers with Security Admin or Security Auditor roles can programmatically retrieve security posture findings.
Affected endpoints:
Fixed
Document Owner and Viewer roles for staking endpoints
Products: Staking
Scope: API + SDKs
-
What's new
Adds missing Owner and Viewer roles to endpoint permission documentation for staking list endpoints. These roles were already permitted at runtime but not documented. -
Impact
Customers with Owner or Viewer roles now see accurate permission documentation for staking endpoints.
Affected endpoints:
v26.0.0
Changelog
2026-08-10
Breaking Change
Make ContractAttributes fields optional
Products: Contract Templates
Scope: API + SDKs
-
What's new
Removes the required constraint fromuseCases,standards, andauditorfields in theContractAttributesschema to match actual API behavior where these fields may be absent for non-EVM templates. -
Impact
SDK-generated types for these fields change from required/non-nullable to optional/nullable, requiring code updates where these fields are accessed.
Affected endpoints:
Changed
Expand TravelRuleVASP response schema documentation
Products: Travel Rule
Scope: API + SDKs
-
What's new
Documents additional fields returned by the Travel Rule VASP endpoints, including GLEIF registry data, compliance phases, and regulatory status. Also clarifiesfieldsparameter behavior and notes that unrecognized fields should be ignored. -
Impact
Customers can now use the full set of VASP fields returned by the API.
Affected endpoints:
v25.0.0
Changelog
2026-08-02
Breaking Change
Rename issuance field to inflation in staking rewards
Products: Staking
Scope: API + SDKs
-
What's new
Renames theissuancereward field toinflationin Solana staking rewards breakdown to better reflect the reward source. -
Impact
Customers using theissuancefield inSolanaRewardsBreakdownresponses must update their code to useinflationinstead.
Affected endpoints:
Make rewardsAmount nullable in staking schemas
Products: Staking
Scope: API + SDKs
-
What's new
TherewardsAmountfield can now be null for Cosmos-family chains where reward tracking is not supported, instead of returning a misleading zero value. -
Impact
SDK consumers using strict type checking may need to update their code to handle null values for this field.
Affected endpoints:
Remove deprecated estimatedAnnualReward from staking
Products: Staking
Scope: API + SDKs
-
What's new
Removes the deprecatedestimatedAnnualRewardfield from theAdditionalInfoschema, aligning the spec with actual staking service behavior. -
Impact
Clients should stop referencingestimatedAnnualRewardas it has not been populated since November 2025.
Affected endpoints:
Added
Add estimatedActivationTime to ETH staking positions
Products: Staking
Scope: API + SDKs
-
What's new
Adds optionalestimatedActivationTimefield toEthereumBlockchainDataschema, showing when pending ETH positions will activate. -
Impact
Customers can now see estimated activation times for pending or activating ETH staking positions.
Affected endpoints:
Add custom HTTP headers support for webhooks
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds an optionalcustomHeadersfield to webhook configuration, allowing customers to attach up to 10 custom HTTP headers to webhook notifications. -
Impact
Customers can configure webhooks with custom headers for enhanced integration flexibility.
Affected endpoints:
Add new FailureReason enum values for CPN off-ramp orders
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
AddsMISSING_DESTINATION_DETAILSandMISSING_WORKSPACE_DETAILSenum values to indicate when CPN off-ramp orders fail due to missing whitelisted destination or workspace institutional details. -
Impact
Customers can now identify specific reasons for CPN off-ramp order failures related to missing configuration details.
Affected endpoints:
Add OAuth 2.0 authentication support for webhooks
Products: Webhooks V2
Scope: API + SDKs
-
What's new
Adds optional OAuth 2.0 client credentials configuration to webhooks, enabling automatic bearer token authentication when delivering webhook events. -
Impact
Customers can now configure webhooks to authenticate with OAuth 2.0-protected endpoints.
Affected endpoints:
Add fiat off-ramp payment rails for six regions
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
Adds OpenAPI schemas and destination types for CIPS (China), NEQUI (Colombia), FPS_UK (UK), FPS_HK (Hong Kong), InstaPay, and PesoNet (Philippines) payment rails. -
Impact
Customers can use these new payment rails for fiat off-ramp transfers to China, Colombia, UK, Hong Kong, and the Philippines.
Affected endpoints:
Changed
Add whitelisted address schemas for six CPN rails
Products: External wallets
Scope: API + SDKs
-
What's new
Adds payment info schemas for CIPS, NEQUI, FPS_UK, FPS_HK, INSTA_PAY, and PESONET rails to support external wallet whitelisting. -
Impact
Customers can now configure whitelisted addresses for these six payment rails.
Affected endpoints:
Add fiat off-ramp payment rails for six regions
Products: Trading (Beta)
Scope: API + SDKs
-
What's new
Adds OpenAPI schemas and destination types for CIPS (China), NEQUI (Colombia), FPS_UK (UK), FPS_HK (Hong Kong), InstaPay, and PesoNet (Philippines) payment rails. -
Impact
Customers can use these new payment rails for fiat off-ramp transfers to China, Colombia, UK, Hong Kong, and the Philippines.
Affected endpoints:
- Create an order
- Get order details
- Get all offers
- Create a quote
- Get rates
- Get trading provider by ID
- Get providers
v24.0.0
Changelog
2026-07-23
Breaking Change
Promote Earn endpoints from beta to GA
Products: Earn
Scope: API + SDKs
-
What's new
Removes the beta designation from all Earn endpoints, changing the tag from Earn (Beta) to Earn and removing beta disclaimer notes. -
Impact
SDK-generated client code will use updated class and method names based on the new Earn tag.
Affected endpoints:
- List earn lending actions
- Create and execute a lending action (deposit or withdraw)
- Get a single earn lending action
- Get list of earn opportunities
- Get list of earn positions
- Get list of earn providers
- Approve earn provider terms of service
Fix TransactionFee schema field types to string
Products: Transactions
Scope: API + SDKs
-
What's new
Corrects thegasPrice,baseFee, andpriorityFeefield types from number to string to align the OpenAPI spec with actual API behavior. -
Impact
SDK-generated code will now correctly type transaction fee fields as strings, matching the actual API response format.
Affected endpoints:
Remove sortBy query parameter from allowlist endpoint
Products: Connected Accounts (Beta)
Scope: API + SDKs
-
What's new
Removes thesortByquery parameter that allowed sorting byaddedAtorlastSyncedAtfrom the connected accounts allowlist endpoint. -
Impact
Clients currently using thesortByparameter will need to remove it from their requests; results will now use the default sorting behavior.
Affected endpoints:
Added
Add programCallDecodedData for Solana transactions
Products: Transactions
Scope: API + SDKs
-
What's new
Adds a new top-level field to transaction responses that provides decoded instruction data for Solana PROGRAM_CALL operations, including Fireblocks-injected instructions. -
Impact
Customers can access decoded Solana instruction details directly from transaction responses without manual decoding.
Affected endpoints:
- Get a specific transaction by external transaction ID
- Get a specific transaction by Fireblocks transaction ID
- Get transaction history
Add allowedEntityTypes support to tags API
Products: Tags, Vaults
Scope: API + SDKs
-
What's new
Adds optionalallowedEntityTypequery filter to list tags andallowedEntityTypesfield to tag creation and responses. -
Impact
Customers can now specify which entity types a tag can be attached to and filter tags accordingly.
Affected endpoints:
- Get list of tags
- Get a tag
- Update a tag
- Get vault accounts
- Create a new vault account
- Get a vault account by ID
- Get vault accounts (Paginated)
Add allowedEntityTypes support to tags API
Products: Tags
Scope: API + SDKs
-
What's new
Adds optionalallowedEntityTypequery filter to list tags andallowedEntityTypesfield to tag creation and responses. -
Impact
Customers can now specify which entity types a tag can be attached to and filter tags accordingly.
Affected endpoints:
Add ORANGE to Mobile Money provider enum
Products: External wallets
Scope: API + SDKs
-
What's new
Adds ORANGE as a supported mobile money service provider in the MomoPaymentInfo schema for external wallet addresses. -
Impact
Customers can now specify ORANGE as a provider when whitelisting Mobile Money external wallet addresses.
Affected endpoints:
Add Blockchain Link management endpoints (beta)
Products: Blockchain link (Beta)
Scope: API + SDKs
-
What's new
Adds beta endpoints to create, list, retrieve, update, delete, activate, and validate tenant-managed custom blockchains. -
Impact
Customers can register and manage their own EVM-compatible blockchains through the API.
Affected endpoints:
- Create a new blockchain
- List blockchains with pagination and filtering
- Get tenant billing info
- Get the test wallet address
- Get a blockchain by ID
- Update a blockchain
- Delete a blockchain
- Activate a blockchain (triggers activation workflow)
- Trigger validation workflow
Add USDC Gateway deposit automation endpoints (beta)
Products: Vaults
Scope: API + SDKs
-
What's new
Adds beta endpoints to configure, read, update, and disable automated USDC Gateway deposits for vault accounts on a recurring schedule. -
Impact
Customers can automate USDC deposits into Gateway wallets without manual intervention.
Affected endpoints:
- Read the USDC Gateway deposit automations for a vault account
- Set up a USDC Gateway deposit automation for a vault account
- Change a USDC Gateway deposit automation
- Stop a USDC Gateway deposit automation's schedule
Add UTXO label and amount filters to max spendable (beta)
Products: Vaults
Scope: API + SDKs
-
What's new
Adds optional query parameters to filter UTXOs by labels (AND/OR logic), address, and amount range when calculating max spendable amount. -
Impact
Customers can calculate max spendable amounts using only UTXOs matching specific labels, addresses, or amount ranges.
Affected endpoints:
Add rescreen endpoint for rejected transactions
Products: Compliance
Scope: API + SDKs
-
What's new
Adds an endpoint to re-run compliance screening on incoming transactions that were rejected or failed by screening checks, with an option to reset the travel rule message. -
Impact
Customers can programmatically retry compliance screening on rejected transactions instead of manually handling...